Vulnslist

find the latest Cisco vulnerabilities

CVE-2020-3456

A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF protections for the FCM interface. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could take unauthorized actions on behalf of the targeted user.

SeverityHIGH
CVSS8.8
CWECWE-352
KEV
Published
Modified

Related Products

Product Advisory Evidence
Firepower Extensible Operating System cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Secure Firewall Threat Defense (FTD) Software cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Firepower Threat Defense Software cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Firepower Extensible Operating System (FXOS) cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Firepower Extensible Operating System cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Firepower 9000 Series cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Firepower 4100 Series cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Firepower 2100 Series cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software cisco-sa-fxosfcm-csrf-uhO4e5BZ Cisco OpenVuln